Siam Thanat Hack Co., Ltd.

Thailand Digital ID Framework: ETDA, DGA Standards, IAL/AAL Assurance, and Platform Security Verification

The current ETS 11-2566 has three volumes covering the framework, identity proofing and authentication. ETDA Recommendations 18, 19 and 20-2566 were withdrawn on 4 February 2026. Select assurance according to service impact.

Executive Summary and Mandate Overview
Target Audience
IdPs, RPs and government digital identity services, distinguishing licensed providers and platforms within DPS scope
Mandatory Frequency
Select schedules under operator-specific rules, policy and risk, with review after material changes. There is no common annual cycle for all services.
Required Scope
Identity proofing, authentication, electronic signatures, sessions, tokens and account recovery for the deployed architecture
Non-Compliance Risk
Impersonation, identity data leakage, weak recovery and misapplied regulatory requirements

Distinguish identity proofing from authentication

The current ETS 11-2566 has three volumes covering the framework, identity proofing and authentication. ETDA Recommendations 18, 19 and 20-2566 were withdrawn on 4 February 2026. Select assurance according to service impact.

Thailand Digital ID: match standards to the service: Identity proofing: IAL, Authentication: AAL, DGA standards, Test the actual system
Thailand Digital ID: match standards to the service

Distinguish IAL, AAL and DGA standards, then select tests for the actual architecture rather than a universal testing cycle.

  • Identity proofing: IAL — Select assurance for service risk
  • Authentication: AAL — Choose factors and authenticators
  • DGA standards — 1-1 is the overview and 1-2 covers Thai citizens
  • Test the actual system — Verify tokens, sessions and recovery
  • IAL concerns confidence in the claimed identity, covering identity resolution, evidence validation and identity verification at the selected level.
  • AAL concerns authentication of an enrolled user. Levels 1, 2 and 3 have different factor and authenticator requirements. A biometric alone does not establish multi-factor authentication.
  • The identity provider (IdP) and relying party (RP) need explicit responsibilities. A relying party is not a certificate authority.
  • Read any IAL 2.1, 2.2 and 2.3 distinctions in the applicable standard and proofing method. Do not assign fixed chip-reading or liveness recipes to these levels without an exact source.

DGA 1-1 is the overview and 1-2 addresses Thai citizens

DGS 1-1:2564 covers the overview of digital identity for government services. DGS 1-2:2564 covers identity proofing and authentication for natural persons with Thai nationality.

  • Use DGS 1-1:2564 to understand roles and relationships. Its discussion of legal persons does not make DGS 1-2:2564 a corporate identity standard.
  • Government service providers should assess service risk and select suitable IAL and AAL, including supported evidence sources and proofing methods.
  • Set evidence retention under the law, regulation and policy applicable to the actual service. This guide does not impose a universal one-year logging period.
  • Review enrollment, authenticator changes, revocation and account recovery for paths that weaken the intended assurance.

Separate electronic signatures from DPS applicability

ETDA Recommendation 23-2563 provides guidance on electronic signatures. The DPS Royal Decree B.E. 2565 addresses qualifying digital platform services. They do not impose a common penetration-testing cycle on every service.

  • The guidance distinguishes general signatures, reliable signatures, and reliable signatures using a certificate from a certification service provider. Read Sections 9, 26 and 28 in their legal context. Section 28 is not a separate definition of a third signature type.
  • Select a signature method for transaction risk and verify signatory binding, document integrity and certificate trust where certificates are used.
  • Check DPS applicability and any additional duties for platform size or risk. Do not transfer supervised Digital ID provider obligations to every digital platform.
  • Select VA and penetration-testing schedules from the operator-specific requirements, policy and system risk. DPS Sections 18 to 20 do not establish a blanket annual penetration-testing mandate.

Recommended tests for the deployed identity architecture

The following are STH assessment recommendations. Adapt them to deployed protocols, data and authorized scope. They are not quoted statutory requirements.

  • For deployed OAuth 2.0, OIDC or SAML, verify signatures, issuer, audience, redirect URI, state, nonce and replay protection as applicable to the protocol.
  • Test sessions, authenticator binding and revocation, step-up authentication and account recovery, including cross-account token misuse.
  • Where biometrics are used, assess presentation attacks and privacy for supported methods. Application testing is distinct from biometric product certification.
  • Use synthetic data, verify access boundaries, and retain remediation and retest evidence before acceptance.

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
ETS 11-2566 Parts 1 to 3 Distinguish identity proofing from authentication The current ETS 11-2566 has three volumes covering the framework, identity proofing and authentication. ETDA Recommendations 18, 19 and 20-2566 were withdrawn on 4 February 2026. Select assurance according to service impact. According to applicable scope and service risk, not a universal testing cycle
DGS 1-1:2564 and DGS 1-2:2564 DGA 1-1 is the overview and 1-2 addresses Thai citizens DGS 1-1:2564 covers the overview of digital identity for government services. DGS 1-2:2564 covers identity proofing and authentication for natural persons with Thai nationality. According to applicable scope and service risk, not a universal testing cycle
ETDA Recommendation 23-2563 and DPS Royal Decree B.E. 2565 Separate electronic signatures from DPS applicability ETDA Recommendation 23-2563 provides guidance on electronic signatures. The DPS Royal Decree B.E. 2565 addresses qualifying digital platform services. They do not impose a common penetration-testing cycle on every service. According to applicable scope and service risk, not a universal testing cycle
STH assessment recommendations Recommended tests for the deployed identity architecture The following are STH assessment recommendations. Adapt them to deployed protocols, data and authorized scope. They are not quoted statutory requirements. According to applicable scope and service risk, not a universal testing cycle

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Frequently Asked Questions (FAQ)

Key answers and practical guidance addressing common compliance questions.

How do IAL and AAL differ?

IAL concerns confidence in the claimed identity, covering identity resolution, evidence validation and identity verification at the selected level. AAL concerns authentication of an enrolled user. Levels 1, 2 and 3 have different factor and authenticator requirements. A biometric alone does not establish multi-factor authentication.

Does DGS 1-2:2564 cover legal persons?

DGS 1-1:2564 covers the overview of digital identity for government services. DGS 1-2:2564 covers identity proofing and authentication for natural persons with Thai nationality.

Does the DPS decree require annual penetration testing of every platform?

Select VA and penetration-testing schedules from the operator-specific requirements, policy and system risk. DPS Sections 18 to 20 do not establish a blanket annual penetration-testing mandate.

Official source documents

Current ETS 11-2566 Digital ID standards and supporting official sources

Go to the official source

Request a quote